Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons.
This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1.
Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data.
Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/t4wdrost6dh17dh406g792j9wq6xmy6v | Mailing List Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Sep 2025, 15:49
Type | Values Removed | Values Added |
---|---|---|
First Time |
Apache jackrabbit Jcr Commons
Apache jackrabbit Apache |
|
References | () https://lists.apache.org/thread/t4wdrost6dh17dh406g792j9wq6xmy6v - Mailing List, Vendor Advisory | |
CPE | cpe:2.3:a:apache:jackrabbit_jcr_commons:*:*:*:*:*:*:*:* cpe:2.3:a:apache:jackrabbit:*:*:*:*:*:*:*:* |
08 Sep 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
08 Sep 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-08 09:15
Updated : 2025-09-18 15:49
NVD link : CVE-2025-58782
Mitre link : CVE-2025-58782
CVE.ORG link : CVE-2025-58782
JSON object : View
Products Affected
apache
- jackrabbit
- jackrabbit_jcr_commons
CWE
CWE-502
Deserialization of Untrusted Data